Md Rasel Bhuyan

51 posts

Md Rasel Bhuyan banner
Md Rasel Bhuyan

Md Rasel Bhuyan

@Mdrasel1230

I am a Student, Self learner, CTF player and I love cyber security ❤️ErrOr SquaD❤️

Dhaka, Bangladesh Katılım Kasım 2016
404 Takip Edilen152 Takipçiler
KNOXSS
KNOXSS@KN0X55·
*** 2nd #KNOXSS GIVEAWAY! *** Like and RT this TWEET to have a chance to win: * 1 KNOXSS Pro Subscription 3-month There will be 5 winners! 😍 Results of this DRAW will be announced in 72hs. Good luck! 😎
KNOXSS tweet media
English
45
321
445
0
Orange Tsai  🍊
Orange Tsai 🍊@orange_8361·
It looks like Microsoft finally fixed all my Exchange vulnerabilities (including Pwn2Own bugs) ! Here is a small spoiler - You can't imagine how amazing it is when I found Exchange still suffered from Padding Oracle Attack 😻 - #proxylogon-is-just-the-tip-of-the-iceberg-a-new-attack-surface-on-microsoft-exchange-server-23442" target="_blank" rel="nofollow noopener">blackhat.com/us-21/briefing… #BHUSA #DEFCON
English
10
163
744
0
Orange Tsai  🍊
Orange Tsai 🍊@orange_8361·
Yay, my talk is accepted by Black Hat USA! "... 7 vulnerabilities that consist of server-side, client-side, and crypto bugs were found via this attack surface and chained into 3 different attack scenarios: ProxyLogon, ProxyShell and ProxyOracle!" #proxylogon-is-just-the-tip-of-the-iceberg-a-new-attack-surface-on-microsoft-exchange-server-23442" target="_blank" rel="nofollow noopener">blackhat.com/us-21/briefing… #BHUSA
Orange Tsai  🍊 tweet media
English
26
186
1K
0
Youssef Sammouda (sam0)
Youssef Sammouda (sam0)@samm0uda·
Account takeover of Instagram accounts due to unrestricted permissions of third-party application's generated tokens ( $18K ) : ysamm.com/?p=684
English
16
150
708
0
Youssef Sammouda (sam0)
Youssef Sammouda (sam0)@samm0uda·
Here's the third bug. Multiple bugs were chained to achieve Facebook account takeover. Facebook account takeover due to unsafe redirects after the OAuth flow ( $30k ) ysamm.com/?p=667
Youssef Sammouda (sam0)@samm0uda

I had a crazy week in February in which i was able to find 3 interesting account takeovers in Facebook and resulted a total of $100k in bounties. I'm sharing details about two of them and soon the third: ysamm.com/?p=646 ysamm.com/?p=654

English
11
117
460
0
Rayhan0x01
Rayhan0x01@Rayhan0x01·
Just like OSCP, my OSWE has also been a fast-paced journey of only 30 days and passing it on the 1st attempt! Sharing my #OSWE experience in a few words and some tips and pointers for someone willing to take on the course: rayhan0x01.github.io/web/2021/04/12…
English
5
119
400
0
Rayhan0x01
Rayhan0x01@Rayhan0x01·
I am ecstatic to share that I passed the #OSWE exam on my 1st attempt! The 48h long exam was the most thrilling exam I went through so far. Loved the course contents and especially the extra lab machines were super fun! Thanks for such a neat course @offsectraining #ITriedHarder
Rayhan0x01 tweet media
English
17
5
207
0
TariKul IsLam
TariKul IsLam@sa1tama0·
@Mdrasel1230 আমাদেরও কিছু টিপস্ দেন।
বাংলা
1
0
0
0
Rohan
Rohan@_Base_64·
Just got my first $10k bounty on @Hacker0x01. Bug: The site was trying to add document from AWS bucket to the main site with POST request,it contains Param named KEY with URL path as value. I tried directory traversal on that param,and it dislcose full bucket with credentials.
Rohan tweet media
English
32
69
663
0